If you work in Tech/IT/Security today everyone is talking about TeamViewer.
Wanna know what happened and how you can easily triage cases like this in the future as a SOC Analyst?
Allow me to share, a 🧵:
The TeamViewer Application is used by IT Professionals and everyone who lives far away from home but still has to deal with their families’ IT problems.
It allows you to remotely login to any computer that shares some session information with you.
What happened recently was that TeamViewer announced they might have been compromised
Walkthrough 🚶🚶♀️🚶♂️ - What does all of this mean and why should I care?!
In the last post I shared the screenshot above with you ⬆️
& wanted to know what you would do if you see this after an alert was triggered when a new account logged into one of the machines in your company network
First up, what do you need to do as a SOC Analyst when you see a new alert?! 🚨🤨🔍
Brute Force attacks are very common lateral movement / initial access vectors because humans are inherently bad at remembering long complex passwords.
💡 What is the difference between brute-force, password spraying and credential stuffing?
Brute-Force - attackers use common usernames / password combos (e.g. root 4 linux & administrator 4 windows)
Password Spraying - one/few passwords against many accounts (internal/external)
Credential Stuffing - known credentials 4 computers that they did not yet compromise